Ivanti EPMM vulnerabilities exploited in the wild (CVE-2025-4427, CVE-2025-4428)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-22460 | Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges. Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-22462 | An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthentic An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2025-4428 +1 in the same advisory: …4427 | Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed. Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated. | 8.8 group max | 86% | KEV |
| largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 11.12.0.5 | nstitutions. Ivanti has released EPMM versions with fixes – 11.12.0.5, 12.3.0.2, 12.4.0.2 , 12.5.0.1 – and is “actively collabora |
| ipv4 | 12.3.0.2 | . Ivanti has released EPMM versions with fixes – 11.12.0.5, 12.3.0.2, 12.4.0.2 , 12.5.0.1 – and is “actively collaborating with |
| ipv4 | 12.4.0.2 | as released EPMM versions with fixes – 11.12.0.5, 12.3.0.2, 12.4.0.2 , 12.5.0.1 – and is “actively collaborating with security p |
| ipv4 | 12.5.0.1 | EPMM versions with fixes – 11.12.0.5, 12.3.0.2, 12.4.0.2 , 12.5.0.1 – and is “actively collaborating with security partners, th |
Full article462 words · extracted from helpnetsecurity.com · click to collapse
Attackers have exploited vulnerabilities in open-source libraries to compromise on-prem Ivanti Endpoint Manager Mobile (EPMM) instances of a “very limited” number of customers, Ivanti has confirmed on Tuesday, and urged customers to install a patch as soon as possible.

“The investigation is ongoing and Ivanti does not have reliable atomic indicators [of compromise] at this time. Customers should reach out to our Support Team for guidance,” the company said.
CVE-2025-4427 and CVE-2025-4428
The exploited vulnerabilities are in two currently unnamed open-source libraries integrated into EPMM.
They didn’t have a CVE number when Ivanti reported them to the maintainers of the open-source libraries, but they have now:
- CVE-2025-4427 is an authentication bypass flaw that allows attackers to access protected resources without proper credentials
- CVE-2025-4428 is a remote code execution vulnerability that allows attackers to execute arbitrary code on the target system
The vulnerabilities have been flagged by CERT-EU, the cybersecurity service for the institutions, bodies, offices and agencies of the European Union, so it’s likely that they have been exploited as zero-days (i.e., vulnerabilities unknown to the libraries’ developers and without a patch) to breach some of those institutions.
Ivanti has released EPMM versions with fixes – 11.12.0.5, 12.3.0.2, 12.4.0.2 , 12.5.0.1 – and is “actively collaborating with security partners, the broader security community and law enforcement.” If vulnerable instances can’t be upgraded, Ivanti has laid out possible workarounds and mitigations.
The vulnerabilities affect only the on-prem EPMM product, which is a mobile device management (MDM) and endpoint security solution for enterprises.
Zero-day vulnerabilities affecting Ivanti EPMM are often leveraged by threat actors.
Patches for other Ivanti products
The company has also released security updates and patches for other Ivanti enterprise solutions, each fixing one vulnerability:
- CVE-2025-22462 is a critical authentication bypass flaw in the on-prem Ivanti Neurons for ITSM that could allow remote unauthenticated attackers to gain administrative access to the system
- CVE-2025-22460 stems from default credentials in Ivanti Cloud Services Application, which may allow a local authenticated attacker to escalate their privileges.
- An improper authorization vulnerability (without a CVE number) in the cloud-based Ivanti Neurons for MDM may allow a remote unauthenticated attacker to edit or delete resources.
These vulnerabilities have been reported by outside researchers and there is currently no indication that they are being leveraged in attacks.
UPDATE (May 14, 2025, 09:15 a.m. ET):
“We can confirm that CERT-EU worked on the vulnerability detected in the Ivanti EPMM and collaborated with the vendor,” an EU Commission spokesperson told Help Net Security when asked for additional insight.
UPDATE (May 16, 2025, 09:15 a.m. ET):
ProjectDiscovery and watchTowr researchers have published their technical analysis of the two vulnerabilities.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/05/13/ivanti-epmm-vulnerabilities-exploited-in-the-wild-cve-2025-4427-cve-2025-4428/